42 subscribers
Go offline with the Player FM app!
Podcasts Worth a Listen
SPONSORED


1 Eli Beer & United Hatzalah: Saving Lives in 90 seconds or Less 30:20
FortiJump Higher, Pishi, and Breaking Control Flow Flattening
Manage episode 450778504 series 2606557
This week, we dive into some changes to V8CTF, the FortiJump Higher bug in Fortinet's FortiManager, as well as some coverage instrumentation on blackbox macOS binaries via Pishi.
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/263.html
[00:00:00] Introduction
[00:00:25] V8 Sandbox Bypass Rewards
[00:25:39] Hop-Skip-FortiJump-FortiJump-Higher - Fortinet FortiManager [CVE-2024-47575]
[00:38:07] Pishi: Coverage guided macOS KEXT fuzzing.
[00:44:20] Breaking Control Flow Flattening: A Deep Technical Analysis
[00:55:10] Firefox Animation CVE-2024-9680 - Dimitri Fourny
[00:57:13] Internship Offers for the 2024-2025 Season
Podcast episodes are available on the usual podcast platforms:
-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063
-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt
-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz
-- Other audio platforms can be found at https://anchor.fm/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
281 episodes
Manage episode 450778504 series 2606557
This week, we dive into some changes to V8CTF, the FortiJump Higher bug in Fortinet's FortiManager, as well as some coverage instrumentation on blackbox macOS binaries via Pishi.
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/263.html
[00:00:00] Introduction
[00:00:25] V8 Sandbox Bypass Rewards
[00:25:39] Hop-Skip-FortiJump-FortiJump-Higher - Fortinet FortiManager [CVE-2024-47575]
[00:38:07] Pishi: Coverage guided macOS KEXT fuzzing.
[00:44:20] Breaking Control Flow Flattening: A Deep Technical Analysis
[00:55:10] Firefox Animation CVE-2024-9680 - Dimitri Fourny
[00:57:13] Internship Offers for the 2024-2025 Season
Podcast episodes are available on the usual podcast platforms:
-- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063
-- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt
-- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz
-- Other audio platforms can be found at https://anchor.fm/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
281 episodes
All episodes
×
1 Mitigating Browser Hacking - Interview with John Carse (SquareX Field CISO) 1:46:57

1 Pulling Gemini Secrets and Windows HVPT 1:33:22

1 Session-ception and User Namespaces Strike Again 49:36

1 Extracting YouTube Creator Emails and Spilling Azure Secrets 44:04

1 ESP32 Backdoor Drama and SAML Auth Bypasses 1:14:08

1 Exploiting Xbox 360 Hypervisor and Microcode Hacking 1:19:05

1 Path Confusion and Mixing Public/Private Keys 59:34

1 ZDI's Triaging Troubles and LibreOffice Exploits 57:02

1 Recycling Exploits in MacOS and Pirating Audiobooks 1:17:06

1 Top 10 Web Hacking Techniques and Windows Shadow Stacks 1:12:42

1 Unicode Troubles, Bypassing CFG, and Racey Pointer Updates 41:29

1 Deanonymization with CloudFlare and Subaru's Security Woes 1:07:35
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Machine Learning Attacks and Tricky Null Bytes 45:07
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Linux Is Still a Mess and Vaultwarden Auth Issues 52:18
![Day[0] podcast artwork](/static/images/64pixel.png)
1 FortiJump Higher, Pishi, and Breaking Control Flow Flattening 1:00:38
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Static Analysis, LLMs, and In-The-Wild Exploit Chains 1:22:02
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Attacking Browser Extensions and CyberPanel 58:18
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Hardwear.IO NL, DEF CON 32, and Filesystem Exploitation 1:11:24
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Zendesk's Email Fiasco and Rooting Linux with a Lighter 50:26
![Day[0] podcast artwork](/static/images/64pixel.png)
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Attack of the CUPS and Exploiting Web Views via HSTS 1:08:09
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Future of the Windows Kernel and Encryption Nonce Reuse 33:52
![Day[0] podcast artwork](/static/images/64pixel.png)
![Day[0] podcast artwork](/static/images/64pixel.png)
1 Memory Corruption: Best Tackled with Mitigations or Safe-Languages 58:23
![Day[0] podcast artwork](/static/images/64pixel.png)
1 [discussion] A Retrospective and Future Look Into DAY[0] 1:03:55
![Day[0] podcast artwork](/static/images/64pixel.png)
1 [binary] Bypassing KASLR and a FortiGate RCE 29:47
Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.